Researchers describe a phishing-as-a-service toolkit dubbed BigBear 2.0 that is capable of defeating multi-factor authentication protections. The operation reportedly hit 258 organizations and harvested over 5,000 sets of Microsoft 365 login credentials, putting the affected accounts and the data within them at risk.
Read the full story at Bleeping Computer